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SUMMARY 

PURPOSE: (U//FOU0) To forward to the Intelligence Oversight Board (IOB) of the 
President’s Foreign Intelligence Advisory Board, via the Assistant to the Secretary of Defense 
for Intelligence Oversight (ATSD(IO)), NSA’s quarterly report on its intelligence activities. 

BACKGROUND: (U//FOUOTExecutive Order 12333 and Executive Order 12863 
require Intelligence Community agency heads and Intelligence Community General Counsels 
and Inspectors General, respectively, to report to the IOB on a quarterly basis concerning 
intelligence activities that they have reason to believe may be unlawful or contrary to Executive 
Order or Presidential Directive. The enclosed memorandum covers all reportable activities 
known to the Inspector General and General Counsel. Per PIOB letter of 6 August 1982, 
Agency heads are responsible for reporting separately any additional reportable activities 
known to them, unless the President has specifically instructed that the Board is not to be 
informed. The Director’s signature signifies that no other activities that require reporting are 
known to him. 

RECOMMENDATION: (U) Director sign the enclosed memorandum. 
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NATIONAL SECURITY AGENCY 
CENTRAL SECURITY SERVICE 

FORT GEORGE G- MEADE, MARYLAND 20755-6000 

14 December 2005 

MEMORANDUM FOR THE CHAIRMAN, INTELLIGENCE OVERSIGHT BOARD 

THRU: Assistant to the Secretary of Defense (Intelligence Oversight) 

SUBJECT: (U/ /FOUQ )- Report to the Intelligence Oversight Board on NSA 
Activities - INFORMATION MEMORANDUM 


DOCID: 4165193 



(U/ /FOUQ) - Except as previously reported to you or the President, or 
otherwise stated in the enclosure, we have no reason to believe that any intelligence 
activities of the National Security Agency during the quarter ending 30 September 
2005 were unlawful or contrary to Executive Order or Presidential Directive, and 
thus required to be reported pursuant to Section 1.7.(d) of Executive Order 12333. 

(U //FOUO) The Inspector General and the General Counsel continue to 
exercise oversight of Agency activities by means of inspections, surveys, training, 
review of directives and guidelines, and advice and counsel. These activities and 



(U //FOUO) I concur in the report of the Inspector General and the General 
Counsel and hereby make it our combined report. 



Lieutenant General, U. S. Army 
Director, NSA/Chief, CSS 


Enel: 

Quarterly Report with NSA/CSS Policy 1-23 

DERIVED FROM: NSA/CSSPM 1-52 
DATED: 23NOV04 
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1. (U) INSPECTOR GENERAL ACTIVITIES 


a. (G//DI) During this quarter, the Office of Inspector General (OIG) reviewed 
various intelligence activities of the National Security Agency/Central Security 
Service (NSA/CSS) to determine whether they were conducted in accordance with 
applicable statutes, Executive Orders (EOs), Attorney General (AG) procedures, and 
Department of Defense (DoD) and internal directives. With few exceptions, the 
issues presented were routine and indicated that the operating elements understand 
the restrictions on NSA/CSS activities. (b) (3) - p.l. 86-36 


b. (U//FOUO) The inspection of the|_ 


conducted in 


August 2004 was closed with both intelligence oversight (10) findings rectified. 
Reporting feedback was provided and 10 program processes were documented to 
ensure program sustainability. 


2. (U) GENERAL COUNSEL ACTIVITIES 

(C//3I) The NSA/CSS Office of General Counsel (OGC) reviewed various intelligence 
activities of the NSA/CSS to determine whether they were conducted in accordance 
with applicable statutes, EOs, AG procedures, and DoD and internal directives. The 
OGC advised Agency elements on a number of questions, including the collection and 
dissemination of communications of or concerning U.S. persons (USP); the reporting 
of possible violations of federal criminal law contained in signals intelligence 
(SIGINT) product; the testing of electronic equipment, and the applicability of the 
Foreign Intelligence Surveillance Act (FISA). With few exceptions, the issues 
presented were routine and indicated that the operating elements understand the 
restrictions on NSA/CSS activities. The OGC directed the briefing of employees 

assigned to | [ with reference to the impropriety of tasking the 

U.S. SIGINT System for personal reasons. The OGC did not file any reports with the 
Intelligence Oversight Board during this quarter. 


3. (U) SIGINT ACTIVITIES (b) <d 

(b)(3)-P.L. 86-36 
(b) (3)-50 USC 3024 (i) 

a. (S//S I ) Collection Against U.S. Persons 


(1) (U) Intentional 


(b)(1) 

(b)(3)-P.L. 86-36 


a. 4-TS//0IfDuring this quarter, the Director, NSA/Chief CSS _ 

(DIRNSA/CHCSS) granted approval for consensual collection against]_|U.S. 
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(ft) (l) 

(b\(3)-P.L. 86-36 
(b)(3)-18 USC 798 
(b) (3.) -50 USC 3024 (i) 


persons. DIRNSA/CHCSS also approved non-consensual collection of 


t aken hostage byf 


an 


a 


U.S. Citizens 


ofl 


I The DIRNSA/CHCSS-approved 
consensual collection against | |U.S. persons was routinely terminated this quarter. 

b. (S//SI) The AG granted authority to collect the communications of| [U.S. 
persons during this quarter. 

'(b)(1) 

(b) (3)-P.L. 86-36 

(2) (U) Unintentional 


a— (S//GI//NT frThis quarter, there were ] [ instances in which analysts 

inadvertently collected communications to, from, or about U. S. persons while 
pursuing foreign intelligence tasking. All of the incidents were reported to 
responsible oversight officials, and corrective actions were taken. Imprecise database 

]and typing mistakes resulted in the collection of U. S. 


queries,_ 

person information in | | ofthe aforementioned instances. The queries were 
promptly terminated, and all data retrieved was immediately del eted. The analyst s 
involved were co unseled, and analysts were provided guidance or^ 

(b)(1) 

(b)(3)-P.L. 86-36 

b. (U/ /FOU O ) The NSA/CSS supports the U.S. military and other 
government organizations by performing Operational Readiness Assessments. 

Under a legal agreement established with each organization, an NSA/CSS team 
attempts to exploit the organization’s information systems for the purposes of helping 
them strengthen their defensive information operations posture. T he NSA/CSS OIG 
is conducting an inquiry into an alleged inadvertent targeting of the[ 


! (b) (3) -P. L. 86-36 


_duri ng an authorized Communications Security Ope rational 

Readiness Assessment for the | | The 

OIG will report the outcome upon completion. 

b. - (TS//S -B We reported a delay in database selection term detasking last 
quarter. (See our r eport dated 22 August 2005.) While collecting on an authorized 
foreign target ] | communicants were recognized to be U.S. persons. The 
termination of the selectors associated with the U.S. persons was d irected 
]but t he detasking of the selectors! 


collection at]_ 

error was discovered. The communications contained]" 


As a r esult, 

when the 


(b) (1) 

(b)(3)-P.L. 86-36 
(b)(3)-50 USC 3024(i) 


(b) (1) 

(b)(3)-P.L. 86-36 
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tr o- 


1 




b. (U//FOUO) Dissemination of U.S. Identities 
(1) (U) Intentional 


(b)(1) 

(b)(3)-P.L. 86-36 


-(G//OIHn acc ordanc e with section 7 of USSID SP0018, U.S. identities were 
disseminated | I times during this quarter. The following table shows the 

justification and the number of instances of dissemination. In the “Unmasked by 
Analyst” column, the U.S. identity was revealed in a serialized end product; in the 
“Unmasked at User Request” column, a U.S. identity was released to a user at the 
user’s request. 



(2) (U) Unintentional 


a . (Q/ /Oi tDuring this quarter, the Signals Intelligence Directorate (SID) 
cancelle d | SIGINT products because they contained the identities of U.S. persons, 
organizations, or entities; those products that contained information derived from 
communications of U.S. persons were not reissued. 


b. - 4TS//8 f)[_j released_Ireports containing 

the identities of U.S. persons or based on t he commun ications of persons later 
identified as U.S. persons. In all instances, ! [ cancelled the reports, which 

were either not reissued or were reissued with the proper minimization. 


(b)(1) 

(b)(3)-P.L. 8 


3 


(b) (1) 

(b) (3)-P.L. 86-36 
(b)(3)-SO USC 3024(i) 
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(3) (U) Raw Traffic Dissemination — S1GINT Production Chain 



(b)(1) 

(b)(3)-P.L. 8 


_ __| The SID ensures that the personnel are 

trained by the QGC on NSA/C SS’s legal restrictions and on proper h andling and 


dissemination of SIGINT data! 


l l r 

working in or with SID during this quarter included representatives of| 


S uch persons 



-P.L. 86-36 


4. (U) Other Activities 

a. (U//FQUQ) FISA Incidents 


(b)(1) 

(b)(3)-P.L. 86-36 
(b)(3)-50 USC 3024(i! 


(1) (TS//SI// NI ^- A s reported last quarter an erro r resulted in a large influx of 
NSA/CSS authorized and unauthorized data by an|_ 


(See our report dated 22 August 2005.) The collected data has been screened and the 
unauthorized information has been destroyed. 


(2) (TB/ZBI/flip f 


4 
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(b)(1) 

(b) (3)-P.L. 86-36 
(b)(3)-50 USC 3024(i) 


J The | [ instances that occurred this quarter 
demonstrate NSA’s proper handling of this collection in accordance with NSA’s FISA 
minimization procedures and as described to the FISC by NSA in the relevant 
applications. In the future, such incidents that are handled properly under FISA 
minimization procedures will not be included in this report. 


(b) (1) 

(b) (3)-P.L. 86-36 


I 


(a) (TS//SI//NP) The exploitation 


i 


as authorized by the FISA Court began on 

w* 


"(b) (1) 

(b)(3)-P. 
(b) (3) — 18| 
(b)(3)-5 


terminated! 


] Collection! | waS 

( when the NSA/CSS analyst realized that the person ' E L ‘ 86 
|was a U.S. person not associated with the authorized target. 


Collected data was purged from the 


L 


~|database, and the 
There was no 

unauthorized disclosure or use of this collection, and no reports were generated as a 
result of the inadvertent collection. 


(b)(1) 


(bH-TS//SI//NF) NSA/CSS 

analysts targeted a 

(associated wit 

i the| 

authorized 

| under FISA. | |the analyst learned 

that the individual) 

|was not the expected target,! [ 


I Because NSA does not have 

authority to target thel 

the collected dat^yv^ 

1 

(b) (3)-P.L. 86 


(b)(3)-18 USC 

.86-36 (C) (TB//SI//NF)! 

-50 USC 

| as authorized by the FISA Court. On 


_J steps were taken to stop all tasking 

jThe collected data was identified and deleted from 
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(b) (1) 

(b)(3)-P.L. 86-36 
(b) (3)-18 USC 798 
(b)(3)-50 USC 3024(i) 


NSA/CSS databases. 
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<b) (1) 

(b){3)-P.L. 86-36 
(b) (3)-18 USC 798 
(b) (3)-50 USC 3024(i) 



The collecti onf 


database. 


]was deleted from the 


and the 


'(b). (3)-P.L. 86-36 


c. (U//POW©)-Misuse of the U.S. SIGINT System 


(T9//SI) The NSA/CSS OIG completed the investigati on into the inciden t as reported 
last quarter. (See our report dated 22 August 2005.) 


a military 


language analyst at the | ] deliberately and without an authorized purpose tasked 

the collection of a U.S. person’s email address. The analyst’s database access was 
immediately suspended and access to Sensitive Compartmented Information was 
suspended by the Navy Commander. As a result of this violation and other unrelated 
computer infractions, the analyst received non-judicial punishment from the Navy 
Commanding Officer based on a hearing under Article 15 of the Uniform Code of 
Military Justice. 


d. (U) Assistance to Law Enforcement (b) ( i ) 

(b)(3)-P.L. 86-36 

(9//3ItDuring this quart er, the SID r esponded to | [ request for analytical and 
linguistic assistance from 

e. (U) Working Aids 

(U/ /FQUO) The SID Office of Oversight and Compliance maintains "U.S. Identities in 
SIGINT" and a matrix of dissemination authorities on its web page for use by the 
NSA/CSS Enterprise. The E.O., NSA/CSS Policy Number 1-23, DoD Regulation 
5240.1-R, and USSID SP0018 are also available on-line. 
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